FoxVendor Privacy Policy
How the FoxVendor Shopify app handles store, seller and shopper data.
Who we are
FoxVendor is a multi-vendor marketplace app for Shopify, built and operated by ooThemes. This policy covers the FoxVendor app itself. It does not cover the stores that install it, the sellers who trade inside them, or Shopify. You can reach us at support@oothemes.com.
Two different roles matter for reading the rest of this page:
- Store data. For everything the app reads from or writes to a merchant's Shopify store, and for the shopper data that reaches the app through that store, we act as a processor on that merchant's instructions. The merchant is the controller. Shoppers with questions about their data should contact the store they bought from.
- Our own records. For the account and support information a merchant gives us directly, such as an email thread about a bug, we act as the controller.
Store data we access, and why
The app requests the permissions below at install. Each one exists because a specific feature stops working without it; the app requests no permission it does not use.
| Permission group | Scopes | Why the app needs it |
|---|---|---|
| Products | read_products, write_products | Sellers create and edit their own listings from the vendor portal, including variants, prices and SKUs. Without write access a seller cannot publish a product at all. |
| Product channels | read_publications, write_publications | When you approve a seller's product, the app publishes it to your Online Store channel. Reading publications is how it finds that channel; writing is how the product goes live. |
| Files | read_files, write_files | Product images, seller logos and banners, and the documents a seller uploads for identity verification are stored in your Shopify Files, not on our servers. |
| Discounts | read_discounts, write_discounts | Sellers can issue discount codes limited to their own products, and deactivate them again. The real discount is a Shopify discount so it applies at your checkout. |
| Returns | read_returns, write_returns | Return requests are routed to the seller who shipped the items so they can approve or decline the return on their own line items. |
| Orders | read_orders | Each order is split into one sub-order per seller so the app can calculate that seller's subtotal, commission, tax share and payout, and reverse it when a refund is issued. Read-only on purpose: the app never edits your orders. |
| Locations | read_locations, write_locations | Each seller gets a dedicated Shopify location so stock and fulfillment are attributable to the seller responsible for them. |
| Inventory | read_inventory, write_inventory | Stock a seller sets in the portal is written to that seller's own location, so two sellers listing similar items never consume each other's inventory. |
| Shipping | read_shipping, write_shipping | Per-seller shipping zones and rates are stored as Shopify delivery profiles, so a buyer is charged the rates of the seller they are actually buying from. |
| Merchant-managed fulfillment orders | read_merchant_managed_fulfillment_orders, write_merchant_managed_fulfillment_orders | Moves each order's fulfillment work to the owning seller's location and lets that seller mark their own items fulfilled with tracking, instead of you fulfilling on their behalf. |
The app also subscribes to store notifications for order creation, order fulfillment and refunds, to app uninstall, and to Shopify's three mandatory privacy notifications.
Protected customer data
Because the app reads orders, Shopify treats it as handling protected customer data. Here is exactly what that means in practice.
Order notifications
The order payload Shopify sends includes protected customer fields such as the buyer's name, email address and shipping address. From that payload the app reads only the line items, quantities, prices, discount allocations, tax lines, and the destination country and region codes it needs to attribute tax. The records it writes contain the shop domain, the seller, the Shopify order id, currency, amounts, and each line item's title, quantity and price. No customer name, email address, address or customer id is written to them.
Fulfillment and shipping labels
A seller needs the delivery address to ship the items they sold. When a seller opens one of their orders, the app fetches the shipping address from Shopify's Admin API at that moment and shows it to that seller only. It is not copied into the app's database. If the merchant has connected EasyPost, the same address plus the parcel weight is sent to EasyPost to buy a label; the app then stores the carrier, service, tracking number, cost and a link to the label. The address itself is not written to the app's database, though the label document that link points to is hosted by EasyPost and, like any shipping label, shows the delivery address. Deleting that label is subject to EasyPost's own retention.
Storefront features
Store reviews, store follows, shopper-to-seller messages and abuse reports need to know which shopper acted. That identity comes from Shopify's signed App Proxy request, which supplies a logged_in_customer_id the app can trust; it is never taken from a form field a browser could forge. For those features the app stores the customer identifier, and the content the shopper chose to submit: a display name, star rating and review text; a follow record; message text; or a report reason and description. Public pages show the display name and text, never the customer identifier.
What the app does not store about shoppers
The list below is the same list the app includes when it answers a Shopify customer data request, so a shopper gets one consistent answer.
| Category | Detail |
|---|---|
| Payment and card details | No card number, bank account or payment instrument is stored for shoppers. Checkout and payment happen entirely in Shopify. The only payment references the app holds belong to sellers being paid out. |
| Order history | The app keeps no shopper order archive. Its per-seller order records hold the Shopify order id and the seller's amounts, with no customer column, so an order cannot be traced back to a shopper inside the app. Order history stays in the Shopify admin. |
| Addresses, phone numbers and email addresses | No shipping address, billing address, phone number or email address is saved to the app's database for shoppers. |
| Browsing, device and analytics data | No page views, sessions, IP addresses, device fingerprints or cookie identifiers are stored for shoppers. Sellers may configure their own analytics pixels; the app stores only the seller's pixel id, never shopper events. |
| Shopper account credentials | Shoppers have no account or password in the app. Identity comes from Shopify's signed customer session, so there is no credential to hold. |
Merchant and staff data
When the app is installed, Shopify issues it a session record. That record holds the store domain, the access token, the granted permissions and, for a logged-in staff session, the staff member's name, email address and locale as Shopify supplies them. Sessions are used to call the Shopify API on the store's behalf and are deleted when the app is uninstalled.
Seller data
Sellers are not Shopify users, so the marketplace holds their accounts. For each seller the app stores:
- Account. Name, email address, status, and a password hash produced with scrypt and a per-account random salt. Passwords are never stored or logged in readable form.
- Public profile. Optional shop handle, description, logo, banner and accent colour, plus a verified flag and any badges earned.
- Commercial terms. Commission rate, chosen payout method, and a payout account identifier such as a Stripe Connect account id. That field holds an identifier only — payout API keys are never stored on a seller record.
- Verification. Links to the documents a seller uploaded to your Shopify Files, an optional business note, the review outcome, and a rejection reason if declined.
- Staff accounts. For each additional login under a seller: email address, optional name, a scrypt password hash, the granted permissions, and a one-time invite token that is cleared once the password is set.
- Trading records. Product ownership, sub-orders, balance ledger entries, payouts, coupons, shipping profiles and rates, shipment labels, subscription status, conversations and abuse reports.
- Connected store. If a seller connects their own external store to import products, the app stores that store's platform, domain and API access token. The token is used server-side only and is never sent to a browser.
Third-party services
Shopify is the platform the app runs on and is always involved. Beyond Shopify, application data is held in a managed PostgreSQL database operated for the app.
Every other integration is off until the merchant turns it on by entering their own credentials in the app's settings. Because those are the merchant's own accounts, the merchant is the controller of that processing and their agreement with each provider governs it. The app does not sign a data processing agreement with a provider on the merchant's behalf, and we do not sell personal data or share it for advertising.
| Service | What is sent, and only if enabled |
|---|---|
| Stripe | Seller payouts and seller subscription billing. The app can create a Stripe Connect account for a seller (sending their email address and country), send them to Stripe's own onboarding, and transfer an amount to that account. Stripe, not the app, collects seller identity and bank details. |
| PayPal Payouts | Seller payouts. The app sends the payout amount, currency and the seller's PayPal receiver email address. |
| EasyPost | Shipping labels. The app sends the buyer's delivery address, the parcel weight and the merchant's configured origin address, and receives a label and tracking number. |
| An AI provider chosen by the merchant: OpenAI, Anthropic, Google Gemini, or any OpenAI-compatible endpoint | Optional writing help for product listings. The app sends only the product text a seller is working on — title, description, keywords or tone — and receives suggested copy. No shopper, order or payout data is sent to an AI provider. |
| The merchant's SMTP mail server | Notification email, and the document the app produces when Shopify forwards a customer data request. Recipient address and message content pass through the mail server the merchant configured. |
| Endpoints the merchant registers for outbound notifications | Marketplace events such as an order being created or a payout being paid, sent to a URL the merchant chose and signed with a shared secret so the receiver can verify them. |
How long data is kept, and how it is deleted
The app acts on all three of Shopify's mandatory privacy notifications. This is what each one does.
When the app is uninstalled
The app deletes the store's stored Shopify sessions, including the access token, and clears its cached plan. It stops being able to call the store. Marketplace records are deliberately kept at this point, so an accidental uninstall followed by a reinstall does not destroy a working marketplace.
Store data deletion
Shopify sends a shop redaction request roughly 48 hours after uninstall. On receiving it the app deletes the store's sellers and everything linked to them — products, sub-orders and their line items, ledger entries, payouts, follows, reviews, coupons, shipping profiles and rates, verifications, conversations and messages, abuse reports, staff accounts, connected external stores and their tokens, shipment labels, badges, pixels, wholesale rules and offers — together with the store's marketplace settings and the integration credentials stored in them, seller subscription plans, tax rates, API keys, registered outbound endpoints, any remaining sessions, and its record of processed notifications.
Shopper data deletion
On a customer redaction request the app deletes that shopper's store follows, store reviews, and conversations with sellers including every message in them. Abuse reports are handled differently on purpose: the report is kept as a safety record for the merchant, but the link to the shopper who filed it is removed so the report can no longer be traced back to them.
Shopper data requests
On a customer data request the app gathers everything it holds for that shopper in that store — follows, reviews, conversations with their full message text, and reports — and builds a document that also names the categories it never stores, so the answer is complete either way. It emails that document to the store owner's Shopify contact address. Shopify requires the store owner to forward it to the shopper within 30 days. The app keeps no copy of the document, and never writes it to a log. Delivery depends on the merchant having configured a mail server; when one is missing the app records that the merchant must send the data another way.
Security
These are the controls the app implements. We make no security certification claim — for example SOC 2 or ISO 27001 — and none should be inferred. No system can be guaranteed completely secure.
- Every notification Shopify sends is verified against its HMAC signature before anything is read from it, and every storefront request through the App Proxy is verified the same way. Unverified requests are rejected.
- Stripe notifications are verified with Stripe's signature scheme, using a constant-time comparison and a five-minute replay window. Outbound notifications the app sends are HMAC-signed so the receiver can verify them.
- All traffic to and from the app uses HTTPS.
- Seller and seller-staff passwords are hashed with scrypt using a per-account random salt, and verified in constant time.
- API keys for the app's own REST API are stored as a SHA-256 hash plus a short display prefix. The key itself is shown once at creation and never stored.
- Integration credentials and access tokens are read and used server-side only. Screens that display them show only the last four characters; full values are never returned to a browser.
- Public endpoints, including seller sign-in, seller signup and the storefront pages, are rate limited per IP address.
- Logs record counts, topics and identifiers so problems can be diagnosed. They deliberately exclude shopper personal data, message text and the contents of a data-request document.
- Every database query is scoped to a single store, and seller-owned records are additionally scoped to a single seller, so one store or seller cannot read another's data.
Your rights
Depending on where you live you may have the right to access, correct, delete or receive a copy of your personal data, and to object to or restrict its processing. How to exercise those rights depends on who holds your data:
- Shoppers should contact the store they bought from. That merchant is the controller, and Shopify's privacy notifications are the route by which the app answers or acts on the request.
- Sellers should contact the operator of the marketplace they joined, who can edit or remove their account. You can also write to us at support@oothemes.com and we will help.
- Merchants can write to us at support@oothemes.com, or uninstall the app to trigger the deletion described above.
We answer requests sent to support@oothemes.com within 30 days. We may need to route a request to the merchant who controls the data, and we will say so if that happens.
International transfers
The app and the services it can be connected to operate internationally, so data may be processed outside the country where it was collected, including in the United States. Each provider publishes its own terms for those transfers, and the merchant's agreement with any provider they enabled governs them.
Children
FoxVendor is a business tool for merchants and the sellers who trade in their stores. It is not directed at children, and we do not knowingly collect personal data from children. If you believe a child's data has reached us, write to support@oothemes.com and we will remove it.
Changes to this policy
When the app's data handling changes, we update this page and the date at the top. The version published here is always the current one, so it is worth re-reading after a significant app update.
Contact
Privacy questions, data requests and security reports all go to support@oothemes.com. This page describes how the app works; it is not legal advice, and merchants remain responsible for their own store's privacy notice.